Skip to content

TechMedia

Header Image
Category

HIGH

385 Posts

Featured

Posted byWpmaster
[Microsoft.NetCore.App.Runtime.win-arm] .NET Remote Code Execution Vulnerability
Posted byWpmaster
[github.com/traefik/traefik/v2] Traefik HTTP header parsing could cause a denial of service
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Exposure of Sensitive Information Through Metadata
Posted byWpmaster
[github.com/answerdev/answer] Answer vulnerable to Insertion of Sensitive Information Into Sent Data

[io.jenkins.plugins:rest-list-parameter] Stored XSS vulnerability in Jenkins REST List Parameter Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/16/2022

REST List Parameter Plugin 1.3.0 and earlier does not escape a parameter name reference in embedded JavaScript.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
REST List Paramete…

[org.jenkins-ci.plugins:extra-columns] Stored XSS vulnerability in Jenkins Extra Columns Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/16/2022

Extra Columns Plugin 1.22 and earlier does not escape parameter values in the build parameters column.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. Additionally, a view contai…

[org.jenkins-ci.plugins:build-with-parameters] Stored XSS vulnerability in Jenkins Build With Parameters Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/16/2022

Build With Parameters Plugin 1.5 and earlier does not escape parameter names and descriptions.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Build With Parameters Plugin 1.5.1 …

[io.jenkins.plugins:artifact-repository-parameter] Stored XSS vulnerability in Jenkins Artifact Repository Parameter Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/14/2022

Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Artifact Repository Param…

[org.jenkins-ci.plugins:claim] XSS vulnerability in Jenkins Claim Plugin

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/21/2022

Claim Plugin 2.18.1 and earlier does not escape the user display name shown in claims.
This results in a cross-site scripting (XSS) vulnerability exploitable by attackers who are able to control the display names of Jenkins users, either via the securi…

[cakephp/cakephp] CakePHP allows method override parameters to bypass CSRF checks

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202201/14/2023

A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request…

[org.jenkins-ci.main:jenkins-core] Stored XSS vulnerability in Jenkins on new item page

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/13/2022

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names …

[org.jenkins-ci.main:jenkins-core] Reflected XSS vulnerability in Jenkins markup formatter preview

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/13/2022

Jenkins allows administrators to choose the markup formatter to use for descriptions of jobs, builds, views, etc. displayed in Jenkins. When editing such a description, users can choose to have Jenkins render a formatted preview of the description they…

[org.jenkins-ci.main:jenkins-core] Improper handling of REST API XML deserialization errors in Jenkins

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202212/14/2022

Jenkins provides XML REST APIs to configure views, jobs, and other items. When deserialization fails because of invalid data, Jenkins 2.274 and earlier, LTS 2.263.1 and earlier stores invalid object references created through these endpoints in the Old…

[Microsoft.AspNetCore.App.Runtime.linux-musl-arm] ASP.NET Core and Visual Studio Denial of Service Vulnerability

  • Posted inHIGH
  • Posted byWpmaster
  • 05/25/202211/04/2022

A denial-of-service vulnerability exists in the way Kestrel parses HTTP/2 requests. The security update addresses the vulnerability by fixing the way the Kestrel parses HTTP/2 requests. Users are advised to upgrade.
References

https://nvd.nist.gov/vul…

Posts navigation

Previous Posts 1 … 26 27 28 29 30 … 39 Next Posts
TechMedia
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close